Impact
The vulnerability is a use‑after‑free flaw in Windows Hello that lets an authorized local attacker obtain elevated privileges. The flaw results from an improper release of memory after an authentication session ends, allowing the attacker to execute arbitrary code in a privileged context and potentially take full control of the affected machine.
Affected Systems
Microsoft Windows 10 version 21H2, Microsoft Windows 10 version 22H2, Microsoft Windows 11 version 23H2, Microsoft Windows 11 version 24H2, Microsoft Windows 11 version 25H2, Microsoft Windows 11 version 26H1.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity for a local privilege escalation. The EPSS score is not available, so the current probability of exploitation is unknown. The vulnerability is not listed in CISA's KEV catalog, suggesting no publicly known exploit. The likely attack vector is local, requiring an attacker to have some authorization on the target system to trigger the flaw by starting and then terminating a Windows Hello authentication session.
OpenCVE Enrichment